Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS0zdng3LXhmZjYtaDJ2eM4AAU0O
OpenStack Nova instance migration process does not stop when instance is deleted
OpenStack Compute (nova) 2015.1 through 2015.1.1, 2014.2.3, and earlier does not stop the migration process when the instance is deleted, which allows remote authenticated users to cause a denial of service (disk, network, and other resource consumption) by resizing and then deleting an instance.
Permalink: https://github.com/advisories/GHSA-3vx7-xff6-h2vxJSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0zdng3LXhmZjYtaDJ2eM4AAU0O
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: over 2 years ago
Updated: 6 months ago
Identifiers: GHSA-3vx7-xff6-h2vx, CVE-2015-3241
References:
- https://nvd.nist.gov/vuln/detail/CVE-2015-3241
- https://github.com/openstack/ossa/blob/482576204dec96f580817b119e3166d71c757731/ossa/OSSA-2015-015.yaml
- https://launchpad.net/bugs/1387543
- https://security.openstack.org/ossa/OSSA-2015-015.html
- http://rhn.redhat.com/errata/RHSA-2015-1723.html
- http://rhn.redhat.com/errata/RHSA-2015-1898.html
- http://www.securityfocus.com/bid/75372
- https://access.redhat.com/errata/RHSA-2015:1723
- https://access.redhat.com/errata/RHSA-2015:1898
- https://access.redhat.com/security/cve/CVE-2015-3241
- https://bugzilla.redhat.com/show_bug.cgi?id=1232782
- https://github.com/openstack/nova/commit/7ab75d5b0b75fc3426323bef19bf436a258b9707
- https://github.com/openstack/nova/commit/b5020a047fc487f35b76fc05f31e52665a1afda1
- https://github.com/openstack/nova/commit/bf23643e36c8764b4bd532546a2cc04385fe0cff
- https://github.com/advisories/GHSA-3vx7-xff6-h2vx
Blast Radius: 0.0
Affected Packages
pypi:nova
Dependent packages: 0Dependent repositories: 40
Downloads: 7,869 last month
Affected Version Ranges: < 12.0.0.0b3
Fixed in: 112.0.0.0b3
All affected versions:
All unaffected versions: 15.1.5, 16.1.6, 16.1.7, 16.1.8, 17.0.7, 17.0.8, 17.0.9, 17.0.10, 17.0.11, 17.0.12, 17.0.13, 18.0.2, 18.0.3, 18.1.0, 18.2.0, 18.2.1, 18.2.2, 18.2.3, 18.3.0, 19.0.0, 19.0.1, 19.0.2, 19.0.3, 19.1.0, 19.2.0, 19.3.0, 19.3.1, 19.3.2, 20.0.0, 20.0.1, 20.1.0, 20.1.1, 20.2.0, 20.3.0, 20.4.0, 20.4.1, 20.5.0, 20.6.0, 20.6.1, 21.0.0, 21.1.0, 21.1.1, 21.1.2, 21.2.0, 21.2.1, 21.2.2, 21.2.3, 21.2.4, 22.0.0, 22.0.1, 22.1.0, 22.2.0, 22.2.1, 22.2.2, 22.3.0, 22.4.0, 23.0.0, 23.0.1, 23.0.2, 23.1.0, 23.2.0, 23.2.1, 23.2.2, 24.0.0, 24.1.0, 24.1.1, 24.2.0, 24.2.1, 25.0.0, 25.0.1, 25.1.0, 25.1.1, 25.2.0, 25.2.1, 25.3.0, 26.0.0, 26.1.0, 26.1.1, 26.2.0, 26.2.1, 26.2.2, 26.3.0, 27.0.0, 27.1.0, 27.2.0, 27.3.0, 27.4.0, 27.5.0, 27.5.1, 28.0.0, 28.0.1, 28.1.0, 28.2.0, 28.3.0, 29.0.0, 29.0.1, 29.0.2, 29.1.0, 29.2.0, 30.0.0